A major U.S. real estate company was targeted in a sophisticated cyberattack involving the emerging Tuoni command-and-control (C2) and red teaming framework. Threat actors, suspected of impersonating Microsoft Teams corporate contacts, lured an employee into executing a malicious PowerShell one-liner. This initiated a concealed PowerShell process that fetched a secondary script, which used steganography to hide the next-stage payload within a BMP image. The attack chain culminated in the in-memory execution of shellcode and the stealthy loading of TuoniAgent.dll, enabling remote control via the Tuoni C2 server. The attackers leveraged artificial intelligence-generated comments and modular code structure to enhance evasion and operational security.
The Tuoni C2 framework, originally designed for penetration testing and red team engagements, is freely available and has been abused in this incident for malicious purposes. Despite the advanced techniques employed—including AI-assisted code, steganography, and in-memory payload delivery—the intrusion was detected and thwarted by security researchers at Morphisec. The incident highlights the growing risk posed by the dual-use nature of red teaming tools and the increasing sophistication of social engineering and payload delivery methods targeting the real estate sector and beyond.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
In mid-November 2025, reporting based on Morphisec's findings publicly identified the newly emergent Tuoni red-teaming and command-and-control framework as part of the failed attack. Researchers also warned that attackers are increasingly combining AI-generated content, steganography, and in-memory execution to evade defenses.
During the attempted attack, Morphisec said it discovered and blocked the intrusion before the compromise succeeded. The incident was described as an unsuccessful cyberattack against the targeted real estate company.
In October 2025, attackers reportedly targeted a leading U.S. real estate firm by impersonating Microsoft Teams corporate contacts and socially engineering an employee into executing a malicious PowerShell one-liner. The intrusion chain used concealed PowerShell execution, BMP-based payload delivery, shellcode extraction, in-memory execution, inline C# compilation, and loading of TuoniAgent.dll tied to the Tuoni command-and-control framework.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.